“FATF’s Fraud Roadmap Expands Data Risks And Global Surveillance“ Forbes, 2 July 2026
The United Kingdom has assumed the Presidency of the Financial Action Task Force, with UK official Giles Thomson placing fraud at the center of the two year agenda.
Thomson has framed fraud as a threat to national security and financial stability. He points to its estimated $500 billion annual scale and its links to organized crime, including human trafficking and forced labor in scam compounds.
The proposed response suggests greater use of large datasets and real-time information sharing. This will include signals from technology and telecommunications companies alongside financial sector data, as well as faster asset recovery, freezing of fraud proceeds, and stronger international cooperation.
On paper, the mission is difficult to oppose. Fraud, scams and scam compounds are real, with victims on both sides of the screen. The roadmap rests on a dangerous assumption that more data collection will automatically make people safer.
The risk with the proposal is that it leans too heavily on data collection, even though decades of experience in traditional finance suggest the problem is not a lack of information. Banks, exchanges and payment firms already collect vast amounts of identity and transaction data, while the underlying problems of fraud, money laundering and sanctions evasion have not disappeared.
The Traditional Finance Problem FATF Has Not Solved
FATF was created in 1989 by the G7, at a time when governments were trying to build a coordinated response to money laundering through the banking system. Its mandate later expanded to terrorist financing after 9/11, and its recommendations have since become the global template for anti-money laundering rules, payment transparency and virtual asset regulation. The same framework built for banks is now being extended to bitcoin, where the privacy and security risks are structurally different.
The distinction between bitcoin and crypto is important because not all digital assets share the same structure or risk profile. Many crypto projects depend on companies, foundations, insiders or centralized infrastructure, while bitcoin operates as an open, decentralized monetary network with no issuer and a public ledger.
When regulation treats them all as interchangeable, identity linked data can be attached to visible stores of value in ways that create risks not faced by traditional finance.
For decades, banks have operated under anti-money laundering rules, customer due diligence requirements, suspicious activity reporting, sanctions screening and payment transparency obligations. These systems have built one of the world’s largest compliance machines.
The United Nations Office on Drugs and Crime still estimates that 2 to 5% of global GDP is laundered each year, a range that has been cited for decades despite the growth of the global compliance industry.
Major traditional financial institutions have repeatedly been fined or investigated for anti-money laundering and sanctions failures, while the FinCEN Files revealed banks moving vast sums in payments they themselves had flagged as suspicious.
That does not mean compliance achieves nothing; it means the model has limits.
FATF’s approach to fraud follows the same logic on a larger and faster scale, drawing more sectors, bigger datasets and tighter connections between technology platforms, telecoms and financial institutions into the financial intelligence system.
For ordinary users, this means more personal information is collected, passed through more systems and retained in more databases, all in the name of preventing crime.
The same approach becomes more dangerous when applied to bitcoin because bank records, however invasive, are not normally available on a public ledger. Bitcoin’s ledger is open and public, which means that once a regulated exchange connects a real-world identity to a wallet address, the danger is not limited to that one transfer. That address can become the starting point for a map of ownership, with future movements analyzed, clustered and interpreted by exchanges, analytics firms and law enforcement agencies.
Australia has recently provided a live example. On 1 July 2026, AUSTRAC’s Travel Rule for virtual assets came into force. Even small transfers through regulated exchanges can trigger checks that require firms to collect and share identifying information about the parties to the transfer. Users sending funds to personal wallets may also be required to complete additional declarations or verification steps before withdrawals are allowed. That is where ordinary wallet activity begins to be pulled into a regulated identity layer.
Supporters will argue that criminals should not be able to hide behind wallets. The harder question is why every ordinary user should be pushed into systems that link identity, transaction history and asset ownership when the same compliance logic has not eliminated laundering inside the traditional banking system.
There is also a basic technical problem. Criminals who understand digital assets already have options designed to frustrate tracing. The people most likely to be caught are often the most ordinary users, the person withdrawing from an exchange to long-term storage, the person trying to avoid custodial risk, the person who bought bitcoin legally and now has to create another identity trail to move it. That trail can cause real and sometimes physical harm.
France has already shown why this is a concern. A series of violent kidnappings and attempted kidnappings has targeted crypto executives and their families, including the abduction of Ledger co-founder David Balland and his partner, and the attempted kidnapping of the daughter of Paymium CEO Pierre Noizat. Not every attack can be traced to a single leak or regulatory database, but it does demonstrate that when identity, location, wealth signals and crypto ownership become easier to connect, the threat model changes.
Data that appears to be compliance information to a regulator can appear to be a target list to a criminal.
Measuring Success
A serious fraud strategy should be judged by whether it reduces harm, not by how much information it gathers.
The Presidency should be judged by outcomes, not by the expansion of the compliance machine. If fraud losses remain high while more firms, platforms, and sectors are drawn into real-time data sharing, the roadmap may succeed as an implementation project but fail as a fraud strategy.
FATF typically measures progress through its mutual evaluation process, looking at whether countries have implemented its standards, improved risk based supervision and made tangible reforms. That is useful for assessing compliance with FATF rules, but it does not necessarily answer the more important question for the public. Have fraud losses fallen, have victims been protected, and have criminal networks been disrupted?
If the answer to failure is always more data collection, the system can expand even when the underlying problem remains.
The Erosion Of Financial Privacy
Financial privacy erodes gradually through risk assessments, compliance obligations, information sharing partnerships and international standards presented as technical rather than political. Each new threat becomes a reason to collect more information from people who have done nothing wrong.
Self-custody gives people control over their money outside centralized custodians, but it is not a complete privacy shield. Bitcoin withdrawn from a KYC exchange can still be analyzed on the public ledger. Non-custodial tools reduce reliance on exchanges that collect identity data, though they do not eliminate every risk.
Giles Thomson is right that fraud is a serious threat. He is also right that organized crime moves quickly and exploits technology. Speed and scale in enforcement cannot become an excuse to build permanent financial surveillance around everyone else.
If FATF wants an effective approach in digital assets, it needs to understand the difference between a bank ledger and bitcoin’s open public ledger. The same identity collection that may be intrusive in traditional finance can become dangerous in bitcoin, because it can attach named individuals to visible stores of value.
More data does not automatically mean more safety. The evidence suggests it can also mean more risk, more targets and more power handed to systems that have failed to stop financial crime in the first place.





Standardizing international oversight for fraud creates a necessary bridge between regulatory compliance and actual operational security. When data sharing becomes a global mandate, we finally move toward the visibility required to stop organized crime at the source. This evolution reflects the reality that bank transfer fraud has shifted from a simple financial discrepancy to a systemic security failure. We are seeing a 170 percent increase in these attacks across France precisely because the technical infrastructure of banking has outpaced the security controls protecting it. Integrating these fraud signals into a unified threat intelligence model is the only way to reverse this trend.
https://cyrilsimonnet.substack.com/p/bank-transfer-fraud-in-france-is